OWASP Monthly Meeting - August 28, 2013
Hosted by OWASP Los Angeles
Details
Los Angeles OWASP Chapter Board Nominated for Best Chapter Leader (https://www.owasp.org/index.php/WASPY_Awards_2013) Join OWASP today and become a member and show your support by casting your vote!
Topic: Layer 7 DDos Attacks
In this talk we will examine different DoS attack techniques used against cloud services. Many attacks discussed in the presentation target the application layer of the service, are highly efficient and asymmetric. In some cases, a single HTTP request of less than 50 bytes is sufficient to knock out a server until reboot. In addition to describing the attacks, we will also investigate the application design issues that lead to vulnerability, and demonstrate coding fixes as well as cloud based defenses that can be used to mitigate the problem.
Speaker: Cassio Goldschmidt is the founder and a former president of the OWASP Los Angeles Chapter
Cassio Goldschmidt is a globally recognized application security leader with strong background in both product and program-level security. Outside work, Cassio is known for his contributions to Open Web Application Security Project (OWASP), Software Assurance Forum for Excellence in Code (SAFECode), the Common Weakness Enumeration (CWE)/SysAdmin, Audit, Network, Security (SANS) Top 25 Most Dangerous Software Errors, along with contributing to the security education curriculum of numerous universities and helping to create International Information Systems Security Certification Consortium (ISC)2’s Certified Secure Software Lifecycle Professional (CSSLP) certification.
Cassio was one of the three finalist in the first (ISC)² Americas Information Security Leadership (ISLA) Awards 2011 in the Information Security Practitioner category and endowed with the special Community Service Star award during the same occasion. In 2012 Cassio was selected as one of the finalist for the OWASP Web Application Security Person of the Year (WASPY) Award. Cassio holds a number of US patents and is an accomplished writer and presenter in the field of application security.
Thanks to our sponsor SecureAuth:
SecureAuth offers Mobile, Web, and Identity Access Mgmt, including single signon (SSO) and 2-factor authentication for cloud, mobile, and network applications.




